6-8
Cisco ASA Series Firewall CLI Configuration Guide
Chapter6 Configuring Access Rules
Guidelines and Limitations
Per-User ACL Guidelines
The per-user ACL uses the value in the timeout uauth command, but it can be overridden by the
AAA per-user session timeout value.
If traffic is denied because of a per-user ACL, syslog message 109025 is logged. If traffic is
permitted, no syslog message is generated. The log option in the per-user ACL has no effect.
Default Settings
See the “Implicit Permits” section on page6-2.
Configuring Access Rules
To apply an access rule, perform the following steps.